Microsoft / Project Server
24 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2020-0954 | A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected Sh… | MEDIUM | 5.4 | Apr 15, 2020 |
| CVE-2019-1036 | Microsoft Office SharePoint XSS Vulnerability | MEDIUM | 5.4 | Jun 12, 2019 |
| CVE-2019-1033 | Microsoft Office SharePoint XSS Vulnerability | MEDIUM | 5.4 | Jun 12, 2019 |
| CVE-2019-1031 | Microsoft Office SharePoint XSS Vulnerability | MEDIUM | 5.4 | Jun 12, 2019 |
| CVE-2018-8284 | A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framework Remote Code Injection Vuln… | HIGH | 8.1 | Jul 11, 2018 |
| CVE-2018-8254 | An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected Share… | MEDIUM | 5.4 | Jun 14, 2018 |
| CVE-2018-8156 | An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected Share… | MEDIUM | 5.4 | May 9, 2018 |
| CVE-2018-0944 | Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allows an elevation of privilege vulnerability to due how specially crafted w… | HIGH | 8.8 | Mar 14, 2018 |
| CVE-2018-0916 | Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted we… | HIGH | 8.8 | Mar 14, 2018 |
| CVE-2018-0915 | Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted we… | HIGH | 8.8 | Mar 14, 2018 |
| CVE-2018-0914 | Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted we… | HIGH | 8.8 | Mar 14, 2018 |
| CVE-2018-0913 | Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted we… | HIGH | 8.8 | Mar 14, 2018 |
| CVE-2018-0912 | Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted we… | HIGH | 8.8 | Mar 14, 2018 |
| CVE-2018-0911 | Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted we… | HIGH | 8.8 | Mar 14, 2018 |
| CVE-2018-0910 | Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted we… | HIGH | 8.8 | Mar 14, 2018 |
| CVE-2018-0909 | Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted we… | HIGH | 8.8 | Mar 14, 2018 |
| CVE-2017-11876 | Microsoft Project Server and Microsoft SharePoint Enterprise Server 2016 allow an attacker to use cross-site forgery to read content that they are not authoriz… | HIGH | 8.8 | Nov 15, 2017 |
| CVE-2017-8551 | An elevation of privilege vulnerability exists when Microsoft SharePoint software fails to properly sanitize a specially crafted requests, aka "Microsoft Share… | MEDIUM | 6.1 | Jun 15, 2017 |
| CVE-2017-0281 | Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2016, Office Online Server 2016, Office Web Apps 2010 SP2,Office Web Apps 2013 SP1, Project… | HIGH | 7.8 | May 12, 2017 |
| CVE-2015-2503 | Microsoft Access 2007 SP3, Excel 2007 SP3, InfoPath 2007 SP3, OneNote 2007 SP3, PowerPoint 2007 SP3, Project 2007 SP3, Publisher 2007 SP3, Visio 2007 SP3, Word… | HIGH | 9.3 | Nov 11, 2015 |
| CVE-2015-1640 | Cross-site scripting (XSS) vulnerability in Microsoft Project Server 2010 SP2 and 2013 SP1 allows remote attackers to inject arbitrary web script or HTML via a… | MEDIUM | 4.3 | Apr 14, 2015 |
| CVE-2014-0251 | Microsoft Windows SharePoint Services 3.0 SP3; SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013 Gold and SP1; SharePoint Foundation 2010 SP1 and SP2 and… | HIGH | 9.0 | May 14, 2014 |
| CVE-2009-0102 | Microsoft Project 2000 SR1 and 2002 SP1, and Office Project 2003 SP3, does not properly handle memory allocation for Project files, which allows remote attacke… | HIGH | 9.3 | Dec 9, 2009 |
| CVE-2006-6617 | projectserver/logon/pdsrequest.asp in Microsoft Project Server 2003 allows remote authenticated users to obtain the MSProjectUser password for a SQL database v… | MEDIUM | 6.5 | Dec 18, 2006 |
Showing 1 to 24 of 24 CVEs